WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,251–1,300 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Cool Author Box Plugin hm-cool-author-box-widget Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2025-47447 Patchstack
4.3 Medium Listamester Plugin listamester Cross-Site Request Forgery No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-47446 Patchstack
4.3 Medium AHAthat Plugin ahathat Cross-Site Request Forgery Cross-Site Request Forgery to AHA Page Deletion No login needed ≤ 1.6 CVE-2025-4337 Wordfence
6.1 Medium Abundatrade Plugin abundatrade-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.8.02 CVE-2025-4199 Wordfence
6.1 Medium Alink Tap Plugin alink-tap Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.3.1 CVE-2025-4198 Wordfence
6.1 Medium Advanced Reorder Image Text Slider Plugin abundatrade-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-4188 Wordfence
5.5 Medium Gravity Forms WebHooks Plugin Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via Webhook ≤ 1.6.0 CVE-2024-13845 Wordfence
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
8.8 High NewsBlogger Theme newsblogger Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed ≤ 0.2.5.4 CVE-2025-1305 Wordfence
6.1 Medium 1 Decembrie 1918 Plugin 1-decembrie-1918 Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.dec.2012 CVE-2025-3870 Wordfence
6.1 Medium Ajax Comment Form CST Plugin ajax-comment-form-cst Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-3867 Wordfence
6.1 Medium Add Google +1 (Plus one) social share Button Plugin add-google-plus-one-social-share-button Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-3866 Wordfence
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
5.4 Medium Zalo Official Live Chat Plugin zalo-official-live-chat Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-46498 Patchstack
7.1 High Unsafe Mimetypes Plugin unsafe-mimetypes Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.1.4 CVE-2025-46507 Patchstack
4.9 Medium WP AVCL Automation Helper (formerly WPFlyLeads) Plugin woozap Server-Side Request Forgery ≤ 3.4 CVE-2025-46531 Patchstack
6.4 Medium BeerXML Shortcode Plugin beerxml-shortcode Server-Side Request Forgery ≤ 0.7.1 Fixed in 0.8 CVE-2025-46511 Patchstack
4.9 Medium Simple Google Photos Grid Plugin simple-google-photos-grid Server-Side Request Forgery ≤ 1.5 Fixed in 1.6 CVE-2025-46503 Patchstack
4.3 Medium All in One Time Clock Lite Plugin aio-time-clock-lite Cross-Site Request Forgery No login needed ≤ 1.3.326 Fixed in 1.3.326 CVE-2025-46513 Patchstack
7.1 High Hacklog Remote Attachment Plugin hacklog-remote-attachment Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-46530 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High WP Filter Post Category Plugin wp-filter-post-categories Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.4 CVE-2025-46524 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
7.1 High Related Posts via Taxonomies Plugin related-posts-via-taxonomies Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.1 CVE-2025-46520 Patchstack
7.1 High Twitter Card Generator Plugin twitter-card-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.5 CVE-2025-46516 Patchstack
7.1 High PayPal Express Checkout Plugin paypal-express-checkout Cross-Site Request Forgery No login needed ≤ 2.1.2 CVE-2025-46499 Patchstack
7.1 High Navegg Analytics Plugin navegg Cross-Site Request Forgery No login needed ≤ 3.3.3 CVE-2025-46497 Patchstack
4.3 Medium WPVN Plugin wpvn-username-changer Cross-Site Request Forgery No login needed ≤ 0.7.8 CVE-2025-46462 Patchstack
7.1 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.3.0 CVE-2025-46450 Patchstack
4.9 Medium Animate Plugin animate Server-Side Request Forgery ≤ 0.5 CVE-2025-46443 Patchstack
4.3 Medium SCSS-Library Plugin scss-library Cross-Site Request Forgery No login needed ≤ 0.4.1 CVE-2025-46436 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-46249 Patchstack
4.3 Medium CM Answers Plugin cm-answers Cross-Site Request Forgery No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-46246 Patchstack
4.3 Medium CM Ad Changer Plugin cm-ad-changer Cross-Site Request Forgery No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-46245 Patchstack
4.3 Medium Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2025-46243 Patchstack
5.4 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Cross-Site Request Forgery No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-46231 Patchstack
7.5 High WP Headers And Footers Plugin wp-headers-and-footers Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 3.1.1 CVE-2025-2111 Wordfence
4.3 Medium User Registration & Membership PRO – Custom Registration Form, Login Form, and User Profile Plugin Cross-Site Request Forgery Custom Registration Form, Login Form, and User Profile <= 5.1.3 - Cross-Site Request Forgery to User Deletion No login needed ≤ 5.1.3 CVE-2025-3284 Wordfence
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
7.1 High WP Twitter Button Plugin wp-twitter-button Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-39420 Patchstack
7.1 High WP Social Bookmarking Plugin wp-social-bookmarking Cross-Site Request Forgery No login needed ≤ 3.6 CVE-2025-39422 Patchstack
7.1 High WP Sticky Side Buttons Plugin wp-sticky-side-buttons Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-39421 Patchstack
4.3 Medium Style Manager Plugin style-manager Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.2.7 CVE-2025-39425 Patchstack
4.3 Medium illow – Cookies Consent Plugin lgpd-compliant-cookie-banner Cross-Site Request Forgery Cookies Consent plugin <= 0.2.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 0.2.0 CVE-2025-39426 Patchstack
7.1 High mLanguage Plugin mlanguage Cross-Site Request Forgery No login needed ≤ 1.6.1 CVE-2025-39430 Patchstack
7.1 High Bknewsticker Plugin bknewsticker Cross-Site Request Forgery No login needed ≤ 1.0.5 CVE-2025-39433 Patchstack
4.3 Medium Anthologize Plugin anthologize Cross-Site Request Forgery No login needed ≤ 0.8.3 CVE-2025-39437 Patchstack
4.3 Medium Theme Changer Plugin theme-changer Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-39438 Patchstack
7.1 High Review Wave – Google Places Reviews Plugin review-wave-google-places-reviews Cross-Site Request Forgery Google Places Reviews plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.4.7 CVE-2025-39442 Patchstack
4.3 Medium Verge3D Plugin verge3d Cross-Site Request Forgery No login needed ≤ 4.9.0 Fixed in 4.9.3 CVE-2025-39443 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only